Endpoint Cybersecurity GmbH
- Why SSDLC is helping shipping faster and more secure code
- Security User Stories How-To – for product managers and developers
- ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance
- ISA VDA 6.0.3 (part 4) — Information Security Sheet: IT Security / Cyber Security
- ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management
- ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization
- TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1)
- AI Adoption for companies in the USA
- AI Adoption for companies (based on OECD data)
- SOC 2 Type 2 mapping to Secure SDLC Requirements



Delivering often in small increments with Scrum
/in EducationalAgile software development, particularly using Scrum, has revolutionized the way software is built and delivered. At its core, Agile embraces iterative and incremental development, a stark contrast to traditional “waterfall” methodologies. The primary objective is to deliver working software frequently and in small increments, ensuring continuous feedback, adaptability, and rapid value delivery. However, we know […]
Navigating AI Standards and Regulations
/in EducationalNote: This post is written with a lot of help from AI, used to summarize the standards mentioned below. Artificial intelligence (AI) is reshaping industries, but it also brings new risks. From security vulnerabilities to compliance challenges, organizations must balance innovation with responsibility. New standards were created and newer are emerging to guide this […]
Policy vs Standard vs Procedure: why, what, how
/in EducationalEver wondered what the differences between these terms are? We use them in GRC very often, but we rarely think what they mean. This creates in time some stretching of these concepts, meaning that their meanings overlap to a certain degree. A Policy is a high-level, mandatory statement of principles and intent. A Standard […]
Comparing Annex A in ISO/IEC 27001:2013 vs. ISO/IEC 27001:2022
/in EducationalI wrote ages ago this article, where I compared briefly the Annex A in the two versions of the standard: https://www.sorinmustaca.com/annex-a-of-iso-27001-2022-explained/ But, I feel that there is still need to detail a bit the changes, especially that now more and more business are forced to re-audit for the newer standard. Overview of Annex A […]
NIS2 Fulfillment through TISAX Assessment and ISA6
/in EducationalENX has released an interesting article about how NIS2 requirements map to TISAX requirements. For this, there is a short introductory article called “TISAX and Cybersecurity in Industry – Expert Analysis Confirms NIS2 Coverage” and and a full article of 75 pages : https://enx.com/TISAX-NIS2-en.pdf An analysis conducted within ENX’s expert working groups examined how well […]